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CLAIMS 

We claim: 

5 1 . A method for allowing proxies in an Identity System, comprising the 

steps of: 

receiving a request for a first entity to be a proxy for a second entity; 
associating said first entity with one or more credentials of said second entity 
without authenticating said first entity as said second entity; and 
10 allowing said first entity to use said Identity System as said second entity 

based on said one or more credentials of said second entity. 

2. A method according to claim I, wherein said step of receiving a 
request includes the steps of: 
15 providing a notification to said first entity of an ability to be said proxy for 

said second entity; and 

receiving a request fi-om said first entity to be said proxy for said second 

entity. 

20 3. A method according to claim 2, wherein: 

said notification includes an email. 

4. A method according to claim 2, wherein: 

said notification includes a display page for said Identity System. 

25 

5. A method according to claim 1, wherein said step of receiving a 
request includes the step of: 

receiving an indication from said second entity that said first entity can be said 
proxy for a second entity. 

30 

6. A method according to claim 1, wherein said step of receiving a 
request includes the steps of: 
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providing a list of potential proxy candidates; 

providing a search mechanism to add more candidates to said list of potential 
proxy candidates; and 

receiving a selection of one or more of said potential proxy candidates, 
5 including a selection of said first entity. 

7. A method according to claim 1, wherein: 
said credentials includes a distinguished name for said second entity. 

8. A method according to claim 1 , wherein: 

said credentials includes identity profile attributes for said second entity. 

9. A method according to claim 1 , wherein: 

said step of associating includes storing an identification of said second entity 
in a data element used to identify said first entity. 

10. A method according to claim 1 , wherein: 

said step of associating includes storing an identification of said second entity 
in a cookie for said first entity. 

11. A method according to claim 1 , wherein: 

said step of associating includes using an identification of said second entity to 
identify said first entity. 

25 12. A method according to claim 1, wherein said step of associating 

includes the steps of: 

accessing an Identity System cookie for said first entity, said Identity System 
cookie stores an identification of said first entity; 

storing said identification of said first entity from said step of accessing in a 
30 second cookie; and 

storing an identification of said second entity in said an Identity System cookie 
for said first entity. 

Attorney Docket No.: OBLX-01025US0 Express Mail No. EL 897 525 558 US 

oblx/1025/1025.app 




-118- 



13. A method according to claim 12, further comprising the steps of: 
receiving a request to terminate said first entity being a proxy for said second 

entity; 

accessing said identification of said first entity in said second cookie; and 
storing said identification of said first entity in said Identity System cookie for 
said first entity. 

14. A method according to claim 12, further comprising the steps of: 
receiving a request from said first entity to access said Identity System; 
determining whether said Identity System cookie for said first entity exists; 
providing access to said Identity System for said first entity if said Identity 

System cookie for said first entity exists; and 

authenticating said first entity and creating said Identity System cookie if said 
Identity System cookie for said first entity does not exist prior to said step of 
determining, said step of creating includes adding said identification of said first 
entity to said Identity System cookie. 

15. A method according to claim 12, wherein said step of allowing 

includes the steps of: 

receiving a request from said first entity to access a service in said Identity 

System; 

accessing said identification of said second entity in said Identity System 

cookie; 

accessing attributes for said second entity based on said identification of said 
second entity in said Identity System cookie; and 

providing access to said service in said Identity System based on said 
attributes for said second entity. 

16. A method according to claim 1 , wherein: 

said steps of receiving, associating and allowing are performed without said 
first entity providing a password for said second entity. 
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17. A method according to claim 1 , wherein: 

said step of associating verifies that said second entity is a delegated 
administrator having a right to be proxied. 

18. A method according to claim 1 , further comprising the step of: 
delegating a right to be proxied to said second entity, said step of associating 

verifies that said second entity has said right to be proxied. 



10 19. A method according to claim 1, wherein: 

said Identity System is part of an integrated Identity System and Access 
System. 

20. A method according to claim 1 , wherein: 
15 said Identity System is part of an integrated Identity System and Access 

System; and 

said an integrated Identity System and Access System uses said credentials of 
said second entity to authorize said second entity to access resources. 

20 21. A method according to claim 20, wherein: 

said step of allowing does not include using said credentials of said second 
entity to authorize said first entity to access resources. 

22. A method according to claim 1, wherein: 
25 said Identity System is part of an integrated Identity System and Access 

System; and 

said steps of associating and allowing provide for said first entity to be said 
proxy for said second entity in said Identity System but does not provide for said first 
entity to be said proxy for said second entity in said Access System. 



30 



23. A method according to claim 1, wherein: 

said Identity System is part of an integrated Identity System and Access 
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System; 



said step of associating includes the steps of: 

accessing an Identity System cookie for said first entity, said Identity 
System cookie stores an identification of said first entity, and 



System cookie for said first entity; 

said Access System uses a Access System cookie for said first entity, said 
Identity System cookie is separate from said Access System cookie; and 

said Access System cookie for said first entity does not store an indication of 
10 said second entity. 

24. One or more processor readable storage devices having processor 
readable code embodied on said processor readable storage devices, said processor 
readable code for programming one or more processors to perform a method 

15 comprising the steps of: 

receiving a request for a first entity to be a proxy for a second entity; 

associating said first entity with one or more credentials of said second entity 
without authenticating said first entity as said second entity; and 

allowing said first entity to use said Identity System as said second entity 
20 based on said one or more credentials of said second entity. 

25 . One or more processor readable storage devices according to claim 24, 
wherein: 

said credentials includes identity profile attributes for said second entity. 



26. One or more processor readable storage devices according to claim 24, 
wherein: 

said step of associating includes storing an identification of said second entity 
in a data element used to identify said first entity. 



5 



storing an identification of said second entity in said an Identity 



25 



30 



27. 



One or more processor readable storage devices according to claim 24, 



wherein: 
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said step of associating includes the steps of: 

accessing an Identity System cookie for said first entity, said Identity 
System cookie stores an identification of said first entity, 

storing said identification of said first entity fi-om said step of 
5 accessing in a second cookie, and 

storing an identification of said second entity in said an Identity 
System cookie for said first entity; and 
said method fiirther comprises the steps of: 

receiving a request to terminate said first entity being a proxy for said 
10 second entity, 

accessing said identification of said first entity in said second cookie, 

and 

storing said identification of said first entity in said Identity System 
cookie for said first entity. 

15 

28. One or more processor readable storage devices according to claim 27, 
wherein said step of allowing includes the steps of: 

receiving a request ixom said first entity to access a service in said Identity 
System; 

20 accessing said identification of said second entity in said Identity System 

cookie; 

accessing attributes for said second entity based on said identification of said 
second entity in said Identity System cookie; and 

providing access to said service in said Identity System based on said 
25 attributes for said second entity. 

29. One or more processor readable storage devices according to claim 24, 
wherein: 

said steps of receiving, associating and allowing are performed without said 
30 first entity providing a password for said second entity. 

30. One or more processor readable storage devices according to claim 24, 
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wherein: 

said Identity System is part of an integrated Identity System and Access 
System; and 

said steps of associating and allowing provide for said first entity to be said 
5 proxy for said second entity in said Identity System but does not provide for said first' 
entity to be said proxy for said second entity in said Access System. 

3 1 . One or more processor readable storage devices according to claim 24, 
wherein; 

said Identity System is part of an integrated Identity System and Access 
System; 

said step of associating includes the steps of: 

accessing an Identity System cookie for said first entity, said Identity 
System cookie stores an identification of said first entity, and 

storing an identification of said second entity in said an Identity 
System cookie for said first entity; 

said Access System uses a Access System cookie for said first entity, said 
Identity System cookie is separate fi-om said Access System cookie; and 

said Access System cookie for said first entity does not store an indication of 
said second entity. 

32. An apparatus that allows for proxies in an Identity System, comprising: 
one or more communication interfaces; 
one or more storage devices; and 

25 one or more processors in commimication with said one or more storage 

devices and said one or more communication interfaces, said processor performs a 
method comprising the steps of: 

receiving a request for a first entity to be a proxy for a second entity, 
associating said first entity with one or more credentials of said second 
30 entity without authenticating said first entity as said second entity, and 

allowing said first entity to use said Identity System as said second 
entity based on said one or more credentials of said second entity. 



10 



15 



20 
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33. An apparatus according to claim 32, wherein: 

said credentials includes identity profile attributes for said second entity. 

5 34. An apparatus according to claim 32, wherein: 

said step of associating includes storing an identification of said second entity 
in a data element used to identify said first entity. 

35. An apparatus according to claim 32, wherein: 
10 said step of associating includes the steps of: 

accessing an Identity System cookie for said first entity, said Identity 
System cookie stores an identification of said first entity, 

storing said identification of said first entity firom said step of 
accessing in 
15 a second cookie, and 

storing an identification of said second entity in said an Identity 
System cookie for said first entity; and 
said method further comprises the steps of: 

receiving a request to terminate said first entity being a proxy for said 
20 second entity; 

accessing said identification of said first entity in said second cookie, 

and 

storing said identification of said first entity in said Identity System 
cookie for said first entity. 

25 

36. An apparatus according to claim 35, wherein said step of allowing 
includes the step of: 

receiving a request fi"om said first entity to access a service in said Identity 
System; 

30 accessing said identification of said second entity in said Identity System 

cookie; 

accessing attributes for said second entity based on said identification of said 
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second entity in said Identity System cookie; and 

providing access to said service in said Identity System based on said 
attributes for said second entity. 

5 37. An apparatus according to claim 32, wherein: 

said steps of receiving, associating and allowing are performed without said 
first entity providing a password for said second entity. 

38. An apparatus according to claim 32, wherein: 

10 said Identity System is part of an integrated Identity System and Access 

System; and 

said steps of associating and allowing provide for said first entity to be said 
proxy for said second entity in said Identity System but does not provide for said first 
entity to be said proxy for said second entity in said Access System. 

15 

39. An apparatus according to claim 32, wherein: 

said Identity System is part of an integrated Identity System and Access 
System; 

said step of associating includes the steps of: 
20 accessing an Identity System cookie for said first entity, said Identity 

System cookie stores an identification of said first entity, and 

storing an identification of said second entity in said an Identity 
System cookie for said first entity; 

said Access System uses a Access System cookie for said first entity, said 
25 Identity System cookie is separate fi-om said Access System cookie; and 

said Access System cookie for said first entity does not store an indication of 
said second entity. 

40. A method for allowing proxies in a system, comprising the steps of: 

30 receiving an indication that a first entity can be a proxy for a second entity, 

said indication is from said second entity; 

receiving an indication from said first entity to become said proxy for said 
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second entity; 

associating said first entity with one or more credentials of said second entity 
without authenticating said first entity as said second entity; and 

allowing said first entity to use said system as said second entity based on said 
5 one or more credentials of said second entity. 

41 . A method according to claim 40, wherein: 

said step of associating includes storing an identification of said second entity 
in a data element used to identify said first entity. 

10 

42. A method according to claim 40, wherein: 
said step of associating includes the steps of: 

accessing a first cookie for said first entity, said first cookie stores an 
identification of said first entity, 
1 5 storing said identification of said first entity in a second cookie, and 

storing an identification of said second entity in said an first cookie for 
said first entity; and 

said method further comprises the steps of; 

receiving a request to terminate said first entity being a proxy for said 
20 second entity, 

accessing said identification of said first entity in said second cookie, 

and 

storing said identification of said first entity in said first cookie for said 
first entity. 

25 

43. A method according to claim 42, wherein said step of allowing 
includes the steps of: 

receiving a request fi^om said first entity to access a service; 
accessing said identification of said second entity in said first cookie; 
30 accessing attributes for said second entity based on said identification of said 

second entity in said first cookie; and 

providing access to said service based on said attributes for said second entity. 
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44. A method according to claim 40, wherein: 

said steps of receiving, associating and allowing are performed without said 
first entity providing a password for said second entity. 



45. One or more processor readable storage devices having processor 
readable code embodied on said processor readable storage devices, said processor 
readable code for programming one or more processors to perform a method 
comprising the steps of: 



said indication is from said second entity; 

receiving an indication from said first entity to become said proxy for said 
second entity; 

associating said first entity with one or more credentials of said second entity 
15 without authenticating said first entity as said second entity; and 

allowing said first entity to use said system as said second entity based on said 
one or more credentials of said second entity. 

46. One or more processor readable storage devices according to claim 45, 
20 wherein: 

said step of associating includes storing an identification of said second entity 
in a data element used to identify said first entity. 



5 



10 



receiving an indication that a first entity can be a proxy for a second entity. 



47. 



One or more processor readable storage devices according to claim 45, 



25 



wherein: 



said step of associating includes the steps of: 

accessing a first cookie for said first entity, said first cookie stores an 



30 



identification of said first entity, 

storing said identification of said first entity in a second cookie, and 
storing an identification of said second entity in said an first cookie for 



said first entity; and 



said method further comprises the steps of: 
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receiving a request to terminate said first entity being a proxy for said 
second entity, 

accessing said identification of said first entity in said second cookie, 

and 

storing said identification of said first entity in said first cookie for said 
first entity. 

48. One or more processor readable storage devices according to claim 47, 
wherein said step of allowing includes the steps of: 

receiving a request firom said first entity to access a service; 
accessing said identification of said second entity in said first cookie; 
accessing attributes for said second entity based on said identification of said 
second entity in said first cookie; and 

providing access to said service based on said attributes for said second entity. 

49. One or more processor readable storage devices according to claim 45, 
wherein: 

said steps of receiving, associating and allowing are performed without said 
first entity providing a password for said second entity. 
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